7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22271
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy data from arbitrary memory.

CVE-2022-4065
testng General
5.5
MEDIUM
EPSS
0.6%
2022 CWE-22 1 PoC

A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function testngXmlExistsInJar of the file testng-core/src/main/java/org/testng/JarFileUtils.java of the component XML File Parser. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 7.5.1 and 7.7.1 is able to address this issue. The patch is named 9150736cd2c123a6a3b60e6193630859f9f0422b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-214027.

CVE-2022-34392
SupportAssist General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-613 1 PoC

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.

CVE-2022-42865
tvOS General
5.5
MEDIUM
EPSS
0.0%
2022 4 PoCs

This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.

CVE-2022-3564
Kernel General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-119 1 PoC

A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.

CVE-2022-30747
Smart Things General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Intent.

CVE-2022-3112
Kernel General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. amvdec_set_canvases in drivers/staging/media/meson/vdec/vdec_helpers.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.

CVE-2022-35080
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.

CVE-2022-26855
PowerScale OneFS General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerability, leading to a denial of service.

CVE-2022-32755
Security Directory Server General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-91 1 PoC

IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.

CVE-2022-3598
libtiff Networking
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.

CVE-2022-28188
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service.

CVE-2022-35081
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.

CVE-2022-25477
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.

CVE-2022-34683
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 2 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service.

CVE-2022-1719
polonel/trudesk Web
5.5
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page

CVE-2022-21527
MySQL Server Database
5.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CV

CVE-2022-46692
iCloud for Windows Cloud Windows
5.5
MEDIUM
EPSS
0.0%
2022 5 PoCs

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1, iOS 15.7.2 and iPadOS 15.7.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may bypass Same Origin Policy.

CVE-2022-34680
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
5.5
MEDIUM
EPSS
0.1%
2022 CWE-197 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.